SYS::ONLINE
Wasteland.
Briefs1526
Issues20
SinceFeb 2026
LIVE
▣ Breach THAILAND-FINANCE-M 2026-07-24

Thailand Ministry of Finance: China-Linked AI-Driven Espionage Intrusion

"Researchers at Hunt.io, working alongside independent security researcher Bob Diachenko, have uncovered a live cyber-espionage operation against Thailand's Ministry of Finance (MOF) that was still unfolding when…"

Researchers at Hunt.io, working alongside independent security researcher Bob Diachenko, have uncovered a live cyber-espionage operation against Thailand's Ministry of Finance (MOF) that was still unfolding when defenders found it. Between July 9 and July 13, the operator left three publicly accessible directories exposed on a Hong Kong-hosted server, spilling nearly 600 files: exploit code, web shells, custom scripts, compiled implants, stolen credentials, active session material, and AI agent logs. The intrusion was driven largely by Hermes, an open-source autonomous AI agent running in unattended "YOLO" mode, and staged a previously undocumented Go-based implant the operator refers to as Hades.

What Happened

Hunt.io traced the activity to three exposed directories on a Hong Kong server, discovered only because the operator failed to disable directory listing. Inside, investigators found the full working kit of an active intrusion set: exploit code, deployed web shells, compiled Windows and Linux implants, custom tooling, and credentials specifically targeting the MOF.

The standout element was the operational use of Hermes, an open-source autonomous AI agent. Rather than functioning as a chatbot, Hermes acted as an operator assistant capable of executing commands without waiting for human approval. Recovered logs show the framework running in its "YOLO" mode, which permits potentially dangerous commands to run automatically. Within those logs, the agent was observed performing privilege escalation checks, file enumeration, service discovery, and broad reconnaissance across ministry systems.

Alongside the AI tooling, the operator staged Hades, a custom Go-based malware family previously unseen by researchers. The Windows and Linux builds share a common codebase and support encrypted command-and-control communications, persistence, interactive shells, file transfers, and SOCKS proxying, giving the operator flexible, cross-platform control over compromised hosts.

What Was Taken

The exposed infrastructure confirms the operator had already moved well beyond initial access. Investigators recovered active session cookie files and stolen credentials targeting MOF systems, along with evidence of web shells deployed on internal hosts. Together, these artifacts indicate the operator had compromised multiple systems inside the ministry's network.

The presence of live session material is particularly significant: valid cookies and credentials allow an attacker to bypass authentication controls, including some multi-factor protections, and blend in as a legitimate user. While the full scope of exfiltrated documents was not detailed, the targeting of a national finance ministry points squarely at economic, fiscal, and policy intelligence of strategic value to a state sponsor.

Why It Matters

This incident is an early, concrete example of offensive automation being used at scale in a real state-linked operation, not a research demonstration. An autonomous agent running unattended can perform reconnaissance, enumeration, and escalation faster and more consistently than a human operator, compressing the timeline defenders have to detect and respond.

The exposure was accidental. Had the operator remembered to close a single directory listing, the operation, its tooling, and the Hades implant might have remained invisible. That reliance on operator error is a thin margin for defenders to depend on. The combination of AI-driven tradecraft, a novel cross-platform implant, and a high-value government target signals where sophisticated espionage is heading, and defenders should assume this model will be repeated with better operational security next time.

The Attack Technique

The initial intrusion vector remains unknown; the reviewed documents did not reveal how first access was obtained. What is clear is the post-access playbook. Once inside, the operator delegated hands-on-keyboard work to Hermes in YOLO mode, letting the agent autonomously run privilege escalation checks, enumerate files, discover services, and map ministry systems.

Persistence and control were handled by the Hades implant, deployed in both Windows and Linux variants from a shared Go codebase. Hades provided encrypted C2, persistence mechanisms, interactive shell access, file transfer, and SOCKS proxy capability, allowing the operator to pivot deeper into the network. Web shells and harvested session cookies rounded out the toolkit, giving the operator resilient, multi-path access across compromised MOF hosts.

What Organizations Should Do

  1. Hunt for autonomous-agent activity: watch for rapid, machine-paced sequences of privilege checks, file enumeration, and service discovery from a single host or account, which can indicate an AI agent operating unattended.
  2. Invalidate and rotate session material: treat stolen cookies and tokens as a primary threat by shortening session lifetimes, binding sessions to device and network context, and forcing re-authentication on anomalies.
  3. Hunt for Hades indicators: inspect Windows and Linux hosts for unexplained Go binaries with encrypted C2, persistence entries, and SOCKS proxy behavior, and monitor for outbound connections to unfamiliar Hong Kong-hosted infrastructure.
  4. Audit for web shells: scan internet-facing and internal web servers for unauthorized scripts, and monitor web directories for unexpected file writes.
  5. Enforce least privilege and segmentation: limit lateral movement by tightening internal access controls, so a single compromised host cannot be leveraged into network-wide reconnaissance.
  6. Prioritize credential hygiene: deploy phishing-resistant MFA, monitor for anomalous credential use, and rapidly reset exposed accounts identified in threat intelligence.

Sources: Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

TWEET: Thailand's Ministry of Finance breached by China-linked operators using the Hermes AI agent unattended in "YOLO" mode, staging the new Hades implant. ~600 exposed files exposed the live op. Full breakdown: https://wasteland.me/intel/thailand-finance-ministry-hermes-ai-hades-espionage #CyberSecurity #ThreatIntel